Overview
Answers to frequently asked questions concerning the Cybersecurity Regulation are below. Capitalized terms used below have the meanings assigned to them in the definition section of Part 500. “Section” references are to sections of the Cybersecurity Regulation unless otherwise stated.
The Department may revise or update the below information from time to time, as appropriate. These FAQs are explanatory and provided for informational purposes only. In the event of an inconsistency between and FAQ and the Cybersecurity Regulation, the Cybersecurity Regulation prevails.
Next Section
Continue
Covered Entities
Yes. Both HMOs and CCRCs are Covered Entities. Pursuant to the Public Health Law, HMOs must receive authorization and prior approval of the forms they use and the rates they charge for comprehensive health insurance in New York. The Public Health Law subjects HMOs to DFS authority by making provisions of the Insurance Law applicable to them. CCRCs are required by Insurance Law Section 1119 to have contracts and rates reviewed and authorized by DFS. The Public Health Law also subjects HMOs and CCRCs to the examination authority of the Department. As this authorization is fundamental to the ability to conduct their businesses, HMOs and CCRCs are Covered Entities because they are “operating under or required to operate under” DFS authorizations pursuant to the Insurance Law, and whether or not they are regulated by another governmental entity is irrelevant to this determination.
Under New York Banking Law Section 590(2)(b-1), certain entities are exempt from having to register with DFS if the entity notifies DFS that (1) it is acting as a mortgage loan servicer in New York, and (2) complies with all regulations promulgated by DFS applicable to mortgage loan servicers. This mortgage loan servicer notification requirement does not, by itself, render an Exempt Mortgage Loan Servicer a Covered Entity. However, mortgage loan servicers that are otherwise required to have “a license, registration, charter, certificate, permit, accreditation or similar authorization” from DFS are Covered Entities. For example, an exempt mortgage loan servicer that is also an insurance company, banking organization, or foreign banking corporation licensed by the superintendent, is a Covered Entity that must comply with the Cybersecurity Regulation.
Given the increasing cybersecurity risks that all financial services organizations face, DFS strongly encourages all financial institutions, including those Exempt Mortgage Loan Servicers that are not Covered Entities, to adopt cybersecurity protections consistent with those required by the Cybersecurity Regulation.
Yes. Passive Mortgage Loan Servicers are Covered Entities and are required to comply with applicable sections of the Cybersecurity Regulation because they are required to receive authorization from the Department to operate as a Passive Mortgage Loan Servicer under New York Banking Law Section 418.2(e).
Yes. Not-for-profit Mortgage Brokers and not-for-profit Mortgage Bankers are Covered Entities and are required to comply with applicable sections of the Cybersecurity Regulation because they are required to apply for and receive authorization from the Department to become not-for-profit Mortgage Brokers and not-for-profit Mortgage Bankers under 3 NYCRR Section 39.4(e).
Yes. DFS-licensed New York branches, agencies and representative offices of out-of-country foreign banks are Covered Entities required to have a cybersecurity program that complies with applicable sections of the Cybersecurity Regulation. Such cybersecurity programs may be developed and implemented by the branch, agency, or representative office itself or may be adopted from its parent or an Affiliate. No matter whose cybersecurity program the Covered Entity uses, it must comply with all sections of the Cybersecurity Regulation applicable to that branch, agency, or representative office of an out-of-country foreign bank.
New York is a signatory to the Nationwide Cooperative Agreement, revised as of December 9, 1997, an agreement among state banking regulators that addresses supervision in an interstate branching environment. Pursuant to the Agreement, the home state of a state-chartered bank with a branch or branches in New York under Article V-C of the New York Banking Law is primarily responsible for supervising such state-chartered bank, including its New York branches.
In keeping with the Agreement’s goals of interstate coordination and cooperation with respect to the supervision and examination of bank branches, including compliance with applicable laws, DFS defers to the home state supervisor for supervision and examination of New York branches, with the understanding that DFS is available to coordinate and work with the home state in such supervision and examination.
New York branches are required to comply with New York state law, and DFS maintains the right to examine branches located in New York. With respect to the Cybersecurity Regulation, given the ever-increasing cybersecurity risks financial institutions face, DFS strongly encourages all financial institutions, including New York branches of out-of-state domestic banks, to adopt cybersecurity protections consistent with the safeguards and protections of the Cybersecurity Regulation.
Next Section
Continue
Governance
Yes. The Senior Governing Body is defined in Section 500.1(q) and includes an appropriate committee of the board of directors.
Next Section
Continue
Risk Assessment
The Risk Assessment required by Sections 500.9 and 500.2(b) is the foundation of the comprehensive cybersecurity program required by DFS’s Cybersecurity Regulation, and a cyber assessment framework can inform and support a comprehensive Risk Assessment. DFS does not require a specific standard or framework for use in the risk assessment process. Covered Entities can use a framework and methodology that best suits their risk and operations; however, Covered Entities must ensure that their Risk Assessment complies with Section 500.9 by assessing the Covered Entity’s unique risks. Among the widely used frameworks Covered Entities employ are the CRI Profile and the NIST Cybersecurity Framework.
Yes. Section 500.9(a) states that Risk Assessments “shall be reviewed and updated as reasonably necessary, but at a minimum annually, and whenever a change in the business or technology causes a material change to the Covered Entity’s cyber risk.” Accordingly, when a Covered Entity is acquiring or merging with a new company, the Covered Entity will need to do a factual analysis of how the requirements of the Cybersecurity Regulation apply to that particular acquisition. Some important considerations include, but are not limited to, the type of business the acquired company engages in, the target company’s cybersecurity risks including its access to Nonpublic Information, the safety and soundness of the Covered Entity, and the integration of Information Systems. The Department emphasizes that Covered Entities must conduct thorough due diligence and prioritize cybersecurity when considering any new acquisitions.
When a subsidiary or other Affiliate of a Covered Entity presents risks to the Covered Entity’s Information Systems or the Nonpublic Information stored on those Information Systems, those risks must be evaluated and addressed in the Covered Entity’s Risk Assessment, cybersecurity program, and cybersecurity policies (see Sections 500.9, 500.2 and 500.3, respectively). Other regulatory requirements may also apply, depending on the individual facts and circumstances.
The Cybersecurity Regulation covers a broad range of Covered Entities that vary in size, type of business, and scope of operations, among other things. Since the Cybersecurity Regulation takes a risk-based approach, what constitutes a “material change” to a Covered Entity’s cyber risk that requires reviewing and updating their Risk Assessment will vary depending on the specific circumstances of the Covered Entity. When making this determination, Covered Entities should consider various factors, including but not limited to, the industry in which they operate, their size, the type and amount of data they maintain or can access, and the size and nature of potential impact to its cybersecurity risk created by the change in business or technology.
For example, merging with or acquiring another company very likely constitutes a material change that would require reviewing and potentially updating a Covered Entity’s Risk Assessment. Similarly, a plan to migrate or outsource key business processes or other key workloads or data to a Third-Party Service Provider will very likely constitute a material change that would require a review and potential update of the Covered Entity’s Risk Assessment.
Next Section
Continue
Third-Party Service Providers
Section 500.11 requires that a Covered Entity develop and implement written policies and procedures designed to ensure the security of Information Systems and Nonpublic Information that are accessible to, or held by, Third-Party Service Providers. Such policies and procedures must include guidelines for due diligence and contractual protections that address, to the extent applicable, the Third-Party Service Provider’s access controls and use of MFA as well as its use of, and policies on encryption. Covered Entities are ultimately responsible for protecting their Information Systems and the Nonpublic Information on those systems and therefore are expected to ensure Third Party Service Providers implement the controls needed to protect such systems and information.
Yes. If an entity is both a Covered Entity and a Third-Party Service Provider, the entity is responsible for meeting the requirements of the Cybersecurity Regulation as a Covered Entity.
Next Section
Continue
Multi-Factor Authentication (MFA)
MFA means the use of two or more different types of verification to confirm a user’s identity before granting the user access to an Information System. Section 500.12 does not mandate the use of any specific type of MFA. Whether the combination of methods meets the requirements of section 500.12 will depend upon the strength and security of the combined authentication factors. Under Section 500.12, MFA must consist of at least two of the following:
- Knowledge: Something you know (like a password or PIN);
- Possession: Something you have (like a hardware key, mobile authenticator app, or smart card); or
- Inherence: Something you are (like fingerprint or facial recognition).
In other words, using only factors from the same category (e.g., a password + PIN) does not qualify as MFA under Section 500.12. The factors used must come from at least two of the categories above.
Additionally, to qualify as “something you have,” it is not sufficient for the computer to simply “remember” information. Methods without cryptographic proof of possession (e.g., methods that are bound to a device, often in the device’s hardware) and that only rely on device recognition, are policy-based, or rely on software-stored certificates, do not independently qualify as reasonable evidence of possession because they can be easily copied or bypassed. However, these methods may, in combination with other security controls, constitute reasonably equivalent or more secure compensating controls under Section 500.12(b).
A valid “something you have” factor commonly involves cryptographic proof of possession, which means the system can mathematically verify that the key or token is real and unique to the user and associated with a specific device. Cryptographic proof of possession provides reasonable assurances that stolen passwords or cloned devices are not being used to impersonate legitimate users, strengthening protections against account compromise.
The following examples illustrate methods that do not meet requirements for MFA because the methods either: (1) rely on a single factor; or (2) are not securely designed to verify user’s true possession or a device or credential.
| Method / Mechanism | Rationale |
|---|---|
| Password only | Passwords are a single factor. MFA requires the use of two or more different types of verification. |
| Browser cookie (“Remember this device”) | This is a session token that can be easily copied. As such, it does not provide reasonable evidence of possession. It may be useful as a supplemental signal, but not as an independent factor without additional controls to compensate for residual risk. |
| Single Sign-On (SSO) without MFA enforcement | SSO systems are not an authentication factor but rather a system to facilitate persistent authentication across different information systems. While SSO may be appropriate for use in certain circumstances, the user authentication process for the SSO system must use Section 500.12-compliant MFA. See FAQ #21 below for additional information. |
Some policy-based mechanisms can authenticate identity and serve as a factor. These mechanisms regularly show cryptographic proof of possession and have certificates that cannot be exported. Weaker policy-based controls may still contribute to the security of a Covered Entity’s Information Systems; however, these controls must be paired with other security mechanisms to qualify as reasonably equivalent or more secure compensating controls under Section 500.12(b).
The following illustrates methods that must be paired with other security controls to meet the requirements of Section 500.12:
| Method / Mechanism | Rationale |
|---|---|
| Device identifier without cryptographic proof of possession | This is frequently policy-based and, as a result, would not independently provide reasonable evidence of possession when there is no cryptographic proof of possession. |
| Software-based workstation certificates that are not cryptographically bound | This method relies on keys stored in software that can be cloned or exported. As such, it does not independently provide reasonable evidence of possession. Software-based workstation certificates are part of a security control that may, in combination with other controls, constitute reasonably equivalent or more secure compensating controls under Section 500.12(b). |
| Device or credential-based mechanisms that rely on conditional, software store trust (e.g., certain VPN client certificates, MDM compliance signals) | When these mechanisms are conditional, they can be cloned/copied and transferred without the user’s knowledge. In these circumstances, the mechanisms would not independently provide reasonable proof of possession. VPN client certificates and MDM compliance are part of a security control that may, in combination with other controls, constitute reasonably equivalent or more secure compensating controls under Section 500.12(b). |
Covered Entities may use push-based applications (e.g., approve/deny notifications) to satisfy the “something you have” possession factor under Section 500.12, but entities should deploy the applications in a way that incorporates appropriate safeguards to ensure these applications are used securely.
Push-based applications can introduce risk because users can experience MFA fatigue (also known as push bombing) and may approve, by accident or to stop the notifications, fraudulent login attempts. In addition, push-based MFA is not phishing-resistant, making it vulnerable to fake login prompts or session hijacking through real-time phishing attacks.
To reduce these risks, Covered Entities should:
- Enable number matching or challenge-response verification;
- Display contextual login details (e.g., location, IP, application requesting access); and
- Limit the number of push retries and enforce adaptive MFA for suspicious activity.
Without those safeguards, push-based MFA provides weakened assurance and is therefore a less effective and higher risk form of MFA.
Single Sign-On (SSO) services simplify access by allowing users to log in once and reach multiple systems with one set of credentials. However, SSO alone does not meet the requirements of Section 500.12. To be compliant, MFA must be enforced in connection with the user’s login to the SSO system, meaning individuals must use MFA as part of the identity provider’s authentication process. Section 500.12 does not require individuals to use MFA each time the SSO system subsequently shares the authentication token to the systems and applications included in the SSO system’s coverage.
DFS expects Covered Entities to ensure that MFA enforcement is centrally managed, applies consistently to all federated and integrated systems, and cannot be bypassed through legacy logins, direct application access, or API connections that circumvent SSO controls. Covered Entities should also consider the sensitivity of each system when configuring SSO, including decisions regarding which systems are included in the SSO system’s coverage and how often a user must re-authenticate to refresh tokens.
Yes. Even when a Covered Entity uses a third party, including cloud service providers, those systems are still considered part of the Covered Entity’s Information Systems if they store, process, or transmit the Covered Entity’s Nonpublic Information.
Cloud-based email, document hosting, and related services are Information Systems that require the use of MFA. A Covered Entity that is required to comply with Section 500.12 may use reasonably equivalent or more secure compensating controls if the Covered Entity has a CISO, the CISO provides written approval of such use, and the CISO reviews the use at least annually.
It depends. Covered Entities generally will not have to implement MFA for most public websites (e.g., marketing, informational pages). However, MFA is required on public-facing websites to the extent:
- The Information System allows unauthenticated access to the Covered Entity’s other Information Systems; or
- The Information System otherwise poses a material cybersecurity risk to the Covered Entity, its customers, other Information Systems, or Nonpublic Information.
Covered Entities should document these determinations and related risk factors. Additionally, the CISO must ensure that such a determination does not conflict with other requirements under the Cybersecurity Regulation, including those related to privilege access, application security, vulnerability management, or overall governance obligations.
Next Section
Continue
Notice of Cybersecurity Incidents
While most unsuccessful attacks will not require a Covered Entity to notify DFS, the Department encourages Covered Entities to notify DFS of significant unsuccessful attacks.
DFS recognizes that Covered Entities are regularly subject to many attempts to gain unauthorized access to, disrupt or misuse Information Systems and the Nonpublic Information stored on them, and that many of these attempts are thwarted by the Covered Entities’ cybersecurity programs. Notice of especially serious unsuccessful attacks enables DFS to more rapidly identify techniques used by attackers and alert industry, respond quickly to new threats, and continue to protect consumers and the financial services industry.
Yes. Section 500.17(a) requires a Covered Entity that has been impacted by a Cybersecurity Incident that occurred at one of its Third-Party Service Providers to notify DFS of the Cybersecurity Incident. Covered Entities are required to do this regardless of whether the Third-Party Service Provider notifies DFS as well. Reporting Cybersecurity Incidents such as these enables DFS to more rapidly identify techniques used by attackers and alert industry, respond quickly to new threats, and continue to protect consumers and the financial services industry.
Next Section
Continue
Annual Compliance Notifications
If you did not receive an email from DFS after making a submission, email [email protected] with “Confirm My Submission” in the subject line. We will need your name or your company’s name (as it appears on the DFS license) and one of the following for you or your company: DFS License number, NAIC number, NMLS Identification number, or DFS Institution number.
No, a Covered Entity may not submit a Certification of Material Compliance unless the Covered Entity was in material compliance with all applicable requirements of the Cybersecurity Regulation for the calendar year prior to the year of submission. A Covered Entity that was not in material compliance with the Cybersecurity Regulation during the prior calendar year must file an Acknowledgment of Noncompliance.
- Visit Cybersecurity Submissions and Notifications to learn more.
It depends. If a Covered Entity qualifies for a full exemption pursuant to Section 500.19(b), (e), or (g), the Covered Entity does not need to submit an annual compliance notification. If, however, the Covered Entity qualifies for a limited exemption under Sections 500.19(a), (c) or (d), it does need to submit an annual notification regarding its compliance during the previous calendar year with applicable sections of the Cybersecurity Regulation.
- Visit Exemptions from the Requirements of the Cybersecurity Regulation to learn more.
Individual insurance brokers and agents must submit an annual compliance notification unless they are fully exempt under one or more exemptions listed in Section 500.19.
- Visit Exemptions from the Requirements of the Cybersecurity Regulation to learn more.
A Covered Entity must determine whether any noncompliance with the Cybersecurity Regulation was significant in the overall context of the Covered Entity’s circumstances. When making that determination, Covered Entities should consider various factors, including but not limited to, the industry in which they operate, their size, the type and amount of data they maintain or can access, and the nature, duration, scope, and potential impact of the noncompliance.
One example of material noncompliance that would require a Covered Entity to file an Acknowledgment of Noncompliance is the failure to conduct a cybersecurity Risk Assessment since its cybersecurity program must be based on such a Risk Assessment. See Section 500.2(b). Another example of material noncompliance is the failure of a Covered Entity to implement procedures designed to ensure the security of Information Systems and Nonpublic Information that are accessible to, or held by, Third-Party Service Providers, especially in light of the significant cybersecurity risks associated with Third-Party Service Providers.
On the other hand, a single event involving an inadvertent lapse in the operation of the cybersecurity program of short duration and with no or minimal impact is not likely to be considered an instance of material noncompliance that would require the filing of an Acknowledgment of Noncompliance. However, several immaterial violations, when considered in the aggregate, might constitute a material violation, necessitating an Acknowledgment of Noncompliance be filed instead of a Certification of Material Compliance.
No matter which notification is filed, Covered Entities must maintain all relevant records, schedules, and other documentation and data supporting their decision to file that type of notification, including documentation regarding the reasons why such decisions were made. See Section 500.17(b)(3).
Section 500.17(b) requires a Covered Entity’s highest-ranking executive and its CISO or, if the Covered Entity does not have a CISO, the Senior Officer responsible for its cybersecurity program, to sign its annual compliance notification. For Covered Entities that are individual licensees, the annual compliance notification only needs to be signed by the individual as that individual is functionally acting as the highest-ranking executive and Senior Officer responsible for the cybersecurity program of the Covered Entity.
The annual compliance notification must be signed by the highest-ranking executive at a Covered Entity and that Covered Entity’s CISO. The term CISO is defined in Section 500.1(c) as “a qualified individual responsible for overseeing and implementing a covered entity’s cybersecurity program and enforcing its cybersecurity policy.” CISOs employed by an Affiliate or a Third-Party Service Provider may sign the annual compliance notification provided that they meet these standards.
If the Covered Entity’s CISO is employed by a Third-Party Service Provider or an Affiliate, the Covered Entity retains responsibility for compliance with the Cybersecurity Regulation and must, among other things, designate a senior member of the Covered Entity’s personnel responsible for the direction and oversight of the Third-Party Service Provider. While this does not mean the senior member must sign the annual compliance notification for a Covered Entity, they must exercise appropriate oversight throughout the review and notification process.
If a Covered Entity does not have a CISO, then the Senior Officer responsible for the cybersecurity program of the Covered Entity must sign the annual compliance notification along with the CEO or highest-ranking executive of the Covered Entity.
All Covered Entities that do not qualify for an exemption are required to designate a CISO pursuant to Section 500.4(a). A CISO is defined in Section 500.1(c) as “a qualified individual responsible for overseeing and implementing a covered entity’s cybersecurity program and enforcing its cybersecurity policy.”
If the Covered Entity designates an individual that is qualified, and responsible for overseeing and implementing its cybersecurity program and enforcing its cybersecurity policy, then that individual should sign the annual compliance notification as the CISO.
Covered Entities do not need to send supporting documentation when they submit a Certification of Material Compliance, but when they submit an Acknowledgment of Noncompliance, they need to identify sections of the Cybersecurity Regulation that they did not materially comply with, describe the nature and extent of such noncompliance, and provide a remediation timeline or confirm that remediation is complete. No additional explanatory or other materials are required as part of these submissions.
Additionally, the Cybersecurity Regulation requires Covered Entities to maintain records, schedules, and data that support their annual compliance notification (Certification of Material Compliance or Acknowledgment of Noncompliance) for 5 years, and must provide this information to the Department upon request.
Next Section
Continue
Exemptions
Under Section 500.19(a)(1), Covered Entities qualify for a limited exemption if they have fewer than 20 employees and independent contractors of the Covered Entity and its Affiliates. The Cybersecurity Regulation does not set a minimum number of work hours for employees or independent contractors. The ultimate decision regarding how to calculate workforce rests upon the actual relationship between the individual and the Covered Entity rather than how many hours the individual works.
When calculating gross annual revenue for purposes of determining whether a Covered Entity qualifies for an exemption under Section 500.19(a)(2), the Covered Entity must include (1) the gross annual revenue from all of its business operations regardless of whether such operations are located in NY or anywhere else in the world and (2) the gross annual revenue from the New York business operations of its Affiliates. If an Affiliate does not have any gross annual revenue from business operations in New York, its gross annual revenue does not need to be included in the calculation for purposes of qualifying for a Section 500.19(a)(2) limited exemption. The limited exemption set forth in Section 500.19(a) is, and always has been, meant for small businesses, not for small branches or affiliates of large companies.
“Affiliate” is a term defined in the Cybersecurity Regulation as “any Person that controls, is controlled by or is under common control with another Person”, and “control” means “the possession, direct or indirect, of the power to direct or cause the direction of the management and policies of a person, whether through the ownership of stock of such person or otherwise.” Section 500.1(a). The Cybersecurity Regulation defines “Person” as “any individual or entity, including but not limited to any partnership, corporation, branch, agency or association.” Section 500.1(m).
To qualify as a wholly owned subsidiary that is fully exempt from the requirements of the Cybersecurity Regulation pursuant to Section 500.19(b), a Covered Entity must be: (1) directly or indirectly 100 percent owned by another Covered Entity and (2) covered by, and follow, the cybersecurity program of the parent Covered Entity.
Covered Entities that have determined they qualify for an exemption should submit a Notice of Exemption within 30 days of making that determination.
- Learn more about Cybersecurity Submissions and Notifications.
Yes. If there are any changes, you should amend your Notice of Exemption.
- Visit Cybersecurity Submissions and Notifications to learn how.
If a Covered Entity ceases to qualify for a previously claimed exemption, the Covered Entity should, as soon as reasonably possible, notify the Department through the DFS Portal by terminating its previously filed exemption. Under Section 500.19(h), a Covered Entity has 180 days to comply with all applicable requirements of the Cybersecurity Regulation once it ceases to qualify for an exemption.
- Visit Cybersecurity Submissions and Notifications to learn how.
Yes, in certain circumstances. By permission, DFS will approve the filing by certain Covered Entities of Notices of Exemption on behalf of their employees or captive agents who are also Covered Entities. This option, called “Bulk Filing,” will only be available if 50 or more employees or captive agents qualify for the same exemption.
- Visit Cybersecurity Submissions and Notifications to learn more.
If you work for a company that has 50 or more employees who qualify for an exemption, and your company has submitted a Notice of Exemption on your behalf through the bulk submission process, you must ask your employer to terminate your exemption when you stop working for that company. If you cannot confirm that they have done so, you may terminate your exemption.
- Visit Cybersecurity Submissions and Notifications to learn more.
Under Section 500.19(a)(1), which is also referred to as the Small Business Exemption, smaller Covered Entities are exempted from certain requirements of the Cybersecurity Regulation when a Covered Entity and all of its Affiliates combined have a total of fewer than 20 employees and independent contractors. When determining whether a Covered Entity and its Affiliates have fewer than 20 employees and independent contractors, all of the Covered Entity’s employees and independent contractors and all of the Covered Entity’s Affiliates’ employees and independent contractors must be counted regardless of where any of the employees and independent contractors are located.
Note that Affiliate is defined broadly in Section 500.1 as any individual or entity, including but not limited to any partnership, corporation, branch, agency or association, that controls, is controlled by, or is under common control with any other individual or entity, including but not limited to any partnership, corporation, branch, agency or association. For purposes of this definition, control means the possession, direct or indirect, of the power to direct or cause the direction of the management and policies of a person, whether through the ownership of stock of such person or otherwise.
Next Section
Continue